USN-4433-1: OpenJDK vulnerabilities
Johannes Kuhn discovered that OpenJDK incorrectly handled access control contexts. An attacker could possibly use this issue to execute arbitrary code. (CVE-2020-14556) It was discovered that OpenJDK incorrectly handled memory allocation when reading TIFF image files. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-14562) It was discovered that OpenJDK incorrectly handled input data. An attacker could possibly use this issue to insert, edit or obtain sensitive information. (CVE-2020-14573) Philippe Arteau discovered that OpenJDK incorrectly verified names in TLS server's X.509 certificates. An attacker could possibly use this issue to obtain sensitive information. (CVE-2020-14577) It was discovered that OpenJDK incorrectly handled image files. An attacker could possibly use this issue to obtain sensitive information. (CVE-2020-14581) Markus Loewe discovered that OpenJDK incorrectly handled concurrent access in java.nio.Buffer class. An attacker could use this issue to bypass the sandbox restrictions and cause unspecified impact. (CVE-2020-14583) It was discovered that OpenJDK incorrectly handled transformation of images. An attacker could possibly use this issue to bypass sandbox restrictions and insert, edit or obtain sensitive information. (CVE-2020-14593) Roman Shemyakin discovered that OpenJDK incorrectly handled XML files. An attacker could possibly use this issue to insert, edit or obtain sensitive information. (CVE-2020-14621)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-14556?
The severity of CVE-2020-14556 is high.
How can CVE-2020-14556 be exploited?
CVE-2020-14556 can be exploited by an attacker to execute arbitrary code.
Which software versions are affected by CVE-2020-14556?
OpenJDK versions 11.0.8+10-0ubuntu1~20.04, 11.0.8+10-0ubuntu1~18.04.1 are affected by CVE-2020-14556.
How to fix CVE-2020-14556?
To fix CVE-2020-14556, update to OpenJDK version 11.0.8+10-0ubuntu1~20.04 or 11.0.8+10-0ubuntu1~18.04.1.
Where can I find more information about CVE-2020-14556?
More information about CVE-2020-14556 can be found at the following link: [CVE-2020-14556](https://ubuntu.com/security/CVE-2020-14556)